CVE-2026-46627

MEDIUM

Twig: Sandbox resource exhaustion via unbounded `for` / `range()`

Title source: cna
STIX 2.1

Description

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.

Scores

CVSS v3 6.5
EPSS 0.0039
EPSS Percentile 31.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
symfony/twig < 3.26.0
twigphp/Twig < 3.26.0
Published Jul 14, 2026
Tracked Since Jul 15, 2026